Google Exposes Coruna iPhone Exploit Kit Targeting Crypto Wallets: Seed Phrase Theft via Fake Exchanges

Google Exposes Coruna iPhone Exploit Kit Targeting Crypto Wallets: Seed Phrase Theft via Fake Exchanges

N
News Editor 01
2026-07-24 10:20:15
Google's Threat Intelligence Group reveals the Coruna iPhone exploit kit targeting iOS 13.0-17.2.1. It steals crypto wallet seed phrases via fake websites like cloned WEEX. The toolkit has passed from a surveillance firm to Russian spies and a Chinese criminal gang.
CorunaiPhone exploitcryptocurrencyseed phrasecybersecurity

Google's Threat Intelligence Group (GTIG) has uncovered the Coruna iPhone exploit kit, also known as 'CryptoWaters'. This sophisticated toolkit targets iOS versions 13.0 through 17.2.1, packing 23 distinct hacking methods organized into five exploit chains, some of which were previously unknown. The tool first belonged to a surveillance company, then moved to a Russian espionage group, and eventually fell into the hands of a Chinese criminal gang focused on financial theft — reflecting a growing market where state-level cyber weapons are reused by common criminals.

How the Attack Works: Fake Sites to Key Theft

Attackers lure victims with cloned cryptocurrency exchange websites, such as a fake version of WEEX. When an iPhone with a vulnerable iOS version visits the site, a hidden script runs silently in the background. The kit first checks the device model and iOS version for exploitable flaws. It then uses Safari browser vulnerabilities to gain root access. Next, a component named 'PlasmaLoader' scans the device for keywords like 'backup phrase' or 'bank account'. Finally, it targets popular wallets including MetaMask, Exodus, Coinbase Wallet, and Bitget to steal seed phrases and private keys, exfiltrating them to a hacker-controlled server.

Origin Dispute: US Government Tool Leaked?

Security firm iVerify claims the Coruna code closely resembles tools developed by the U.S. government, potentially having 'spun out of control'. However, Kaspersky experts argue there is no solid proof that the code was copied from known government frameworks. Regardless of its origin, the toolkit cost millions of dollars to develop and is now being used against ordinary users.

Industry Reaction: A Wake-Up Call for Mobile Security

The discovery signals a 'second-hand market' for cyber weapons, where state-level spy tools are recycled for financial crimes. Targeted spyware has now evolved into mass attacks against anyone holding crypto. Researchers expect hackers to become even better at hiding malicious scripts inside everyday websites.

The simplest defense is keeping iPhones updated. Google and Apple confirm that iOS 17.3 and later are not affected. For older devices that cannot be upgraded, enabling 'Lockdown Mode' stops the exploit — the kit is designed to abort if it detects Lockdown Mode, as it makes the device too hard to crack.

Cryptocurrency and mobile security involve high risks. This article is based on current security reports and does not guarantee complete protection. Always refer to official Apple security guides for device-specific advice.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
1300

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.